WPCOM Member
WPCOM Member has 8 disclosed vulnerabilities in the WordSec catalog, reported between 2024 and 2025; all 8 are fixed as of September 2026. Their average CVSS score is 8.6, and the most serious one scores 10.0 out of 10. Severity breakdown: 3 critical and 4 high. 2025 was the busiest year with 5 disclosures.
The most common weakness is Improper Authentication, behind 2 of the records (25%). Other recurring categories include PHP Remote File Inclusion, Cross-Site Scripting.
Every one of the 8 issues recorded for WPCOM Member has a vendor fix available, so running the current release closes all known holes.
4 independent researchers contributed these findings, most of them (4) reported by wesley (wcraft). WPCOM Member is installed on roughly 1,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.
CVE-2024-6297Several WordPress.org Plugins <= Various Versions - Injected Backdoor
Read the full analysisVulnerability Records
WPCOM Member
Author
Lomu
WordPress用户中心插件 / User profile & membership plugin for WordPress WPCOM用户中心插件 使用说明 设置入口:后台用户中心 插件使用可以参考(部分功能为高级版或主题内置,免费版会有区别):https://www.wpcom.cn/docs/themer/member.html 支持功能 前端注册、登录、找回密码页面,注册登录弹框; 前端帐号设置页面,可支持个人资料设置、修改密码、头像设置等; 前端个人中心页面; 社交登录:微信、微博、QQ、Google、Facebook、Twitter、Github; 注册登录表单人机验证:集成WPCOM内置人机验证(免费)、阿里云云盾验证码、腾讯云验证码/防水墙、hCaptcha和Google reCAPTCHA安全验证方式; 注册邮箱验证; 用户黑名单功能; WooCommerce兼容; 用户中心高级版 高级版购买地址:https://www.wpcom.cn/plugins/wpcom-member-pro.html 高级版功能: 内置订单支付系统,可支持微信支付、支付宝以及虎皮椒支付接口; 会员订阅功能; 我的钱包功能,可实现余额支付; 积分功能; 卡密销售功能; 代金券充值功能; 付费查看内容、付费阅读全文; 付费下载内容; 付费复制功能; 邀请码注册功能; 推荐佣金功能; 用户私信功能; 用户关注功能; 系统通知功能; 用户分组功能; 手机号注册登录功能; 扫码登录功能、微信扫码关注公众号登录;
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C